SB2026072183 - Out-of-bounds read in Linux kernel i2c driver
Published: July 21, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-64191)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds read and out-of-bounds write in stub_xfer() in the i2c-stub driver when handling an I2C_SMBUS ioctl with I2C_SMBUS_I2C_BLOCK_DATA and an invalid block length. A local user can issue a crafted ioctl request with data->block[0] greater than 32 to cause a denial of service.
The issue affects the development and test i2c-stub driver, which is not built by default and must be loaded with a chip_addr= parameter.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0526931b16e5a118d367b7bfce7d797e63f7ac69
- https://git.kernel.org/stable/c/1c4ffe6b4f04365485ed58d64c9bb86b46fc9037
- https://git.kernel.org/stable/c/21e87f336ac6303fed54a69b1d0d79a23b25c8d0
- https://git.kernel.org/stable/c/3fd225f3e4cd67ec8ddab1afed9da03c7c43537c
- https://git.kernel.org/stable/c/4bd8635f28c135a08aac6badcd7d9b5cdb34335f
- https://git.kernel.org/stable/c/5f4d2bd028ebb6e4c09a9d64842546022321d4a7
- https://git.kernel.org/stable/c/6036b5067a8199ba7a2dc7b377d4b9dd276d5f9e
- https://git.kernel.org/stable/c/7e9072dbd5f2f17934751873450d2c22080ead80